This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

SKZI (cryptographic information protection tool)

Information Security

SKZI are software and hardware encryption tools certified by the FSB of Russia to protect confidential information and electronic signatures.

What is SKZI in simple words

SKZI (cryptographic information protection tools) are special programs or devices that encrypt data and create electronic signatures. Imagine that you send a letter, but instead of plain text it turns into a set of incomprehensible symbols that only the person who has a special "key" for decryption can read. This is cryptographic protection.

CIPF — types, classes (FSB Order No. 378) and applications CIPF classification: software (CryptoPro CSP), hardware (Rutoken, JaCarta) and software-hardware. Classes: KS1 (external threats), KS2 (internal threats), KV/KA (government information systems). Applications: encryption, digital signature, authentication, VPN. FSB certification is mandatory. CIPF: classification and applications CIPF types Software CryptoPro CSP Hardware Rutoken, JaCarta Software-hardware Combined solutions Classes (FSB Order No. 378) KS1 Protection from external threats KS2 Protection from internal threats KV / KA For government systems Applications Data encryption Digital signature Authentication and VPN ✅ All CIPF in government information systems must have an FSB Russia certificate
SKZI (cryptographic information protection tool) — term diagram

SKZI are used everywhere: in electronic document management, bank transfers, secure communications between government bodies, when submitting reports to the tax authority and in many other areas. Without SKZI, it is impossible to ensure data confidentiality in the digital world — any information transmitted over open communication channels can be intercepted and read by attackers.

In Russia, all SKZI are subject to mandatory certification by the FSB of Russia. This means that before a cryptographic protection tool is allowed for use, it undergoes a strict check for compliance with security requirements. The use of uncertified SKZI in government information systems and for the protection of personal data is prohibited by law.

It is important to understand that cryptographic protection is not only data encryption. SKZI are also used to create an electronic signature (ES), which confirms the authenticity of a document and authorship. An electronic signature created using certified SKZI has the same legal force as a handwritten signature on a paper document.

SKZI are also used for user authentication — when you log into a system using an electronic signature or use a secure communication channel, it is SKZI that verifies the authenticity of your data. This is critically important for preventing unauthorized access to information systems.

Types and classes of SKZI

  • Software SKZI: Cryptographic libraries and modules embedded in applications. Examples: CryptoPro CSP, ViPNet CSP, and the SINTEZM product. They are installed on servers or workstations and provide data encryption and electronic signature creation in a software environment.
  • Hardware SKZI: Physical devices that implement cryptographic operations at the hardware level. Examples: Rutoken and JaCarta tokens, trusted boot hardware modules. They provide a higher level of protection, because cryptographic keys are stored in a protected hardware environment and cannot be extracted by software methods.
  • Software and hardware SKZI: Complexes combining a hardware platform with protected software. Examples: ViPNet Coordinator, CryptoPro HSM. They are used in corporate and government systems where a high level of protection and performance is required.

According to the protection level, SKZI are divided into classes determined by FSB Order No. 378. The main classes:

  • KS1: Protection against external threats (hacker attacks, viruses).
  • KS2: Additional protection against internal threats (unscrupulous employees).
  • KS3: A high level of protection for critically important systems.
  • KV: For government information systems with special requirements.
  • KA: The maximum level of protection, used in systems of special importance.

The choice of SKZI class depends on the type of processed information and the level of threats. For example, to protect personal data in a commercial organization, class KS1 may be sufficient, while for government systems processing secret data, class KA is required. The SKZI class is indicated in the FSB certificate and product documentation.

Application of SKZI

SKZI are used in a wide variety of areas:

  • Data encryption: Protection of information when transmitted over open communication channels (Internet, corporate networks). This is especially important for financial organizations, government bodies and companies working with confidential data.
  • Electronic signature: Creation and verification of electronic signatures for documents, which ensures their legal validity and protection against forgery. Electronic signatures are widely used in electronic document management, when submitting reports and in government services.
  • Authentication: Confirmation of the authenticity of users and systems when accessing information resources. This prevents unauthorized access and increases the overall security level.
  • Secure document management: Ensuring the confidentiality and integrity of documents when exchanged between organizations. The electronic signature technology is based on SKZI.

Services for the research and selection of SKZI help choose the optimal solution for specific tasks. This is an important stage, since the wrong choice of SKZI can lead either to an insufficient level of protection or to excessive costs for a more expensive solution than required.

It is also worth considering that SKZI must be regularly updated, since encryption algorithms are constantly being improved, and hacking methods are becoming more and more sophisticated. In Russia, there is a strict certification system that guarantees that the SKZI used meet modern security requirements. Read more about information protection in the technologies section.

Frequently asked questions

What is SKZI in simple words?

SKZI are programs or devices that encrypt data and create electronic signatures. They turn ordinary data into unreadable code, protecting it from theft and forgery. SKZI are used in electronic document management, bank transfers and secure communications. The SINTEZM product is a certified SKZI for electronic signatures and encryption. The research service will help you choose the optimal SKZI.

What is SKZI?

SKZI (cryptographic information protection tools) are hardware, software and software-hardware complexes for data encryption, protection against unauthorized access and creating electronic signatures. In Russia, all SKZI are subject to FSB certification. The SINTEZM product is a certified SKZI. The research service will help you select the optimal solution.

What are some examples of SKZI?

Examples of software SKZI: CryptoPro CSP, ViPNet CSP, Kontur.Kripto, and the SINTEZM product. Hardware SKZI: Rutoken, JaCarta. Software-hardware: ViPNet Coordinator, CryptoPro HSM. In Russia, only SKZI certified by the FSB are allowed for use. The research service will help you choose the optimal solution for your tasks.

What is SKZI in a tachograph?

SKZI in a tachograph is a cryptographic information protection tool, a special cryptographic chip that encrypts data about the speed, mileage and route of a vehicle. The SKZI unit protects against data forgery, supports the operation of driver cards with an electronic signature and records coordinates via GLONASS/GPS. The service life of the SKZI unit is 3 years. The SINTEZM product is an example of software SKZI.

How to determine the SKZI class?

The SKZI class is determined according to FSB Order No. 378, based on the type of threats, the level of significance and the scale of processed data. Classes: KS1 (protection against external threats), KS2 (protection against internal threats), KS3 (high protection), KV (for government systems), KA (maximum class). The class is indicated in the documentation and the FSB certificate. The SINTEZM product has an FSB certificate. The research service will help determine the required class.

Who can work with SKZI?

Only authorized employees who have completed training and gained access to encryption keys and electronic signatures are allowed to work with SKZI. They must comply with operating rules, keep keys secret and promptly detect hacking attempts. The SINTEZM product is a certified SKZI for corporate use. The training service will help prepare employees.

What is not allowed for a SKZI user?

A SKZI user is prohibited from: transferring keys to third parties, disclosing passwords from media, leaving media unattended, creating backup copies of keys without approval, making changes to SKZI software, and using work keys on personal computers. Violation of the rules entails liability. The SINTEZM product is a certified SKZI with clear operating rules.

Was this information helpful?

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate skzi (cryptographic information protection tool) into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm